Lock It Down
An exam-pace security drill: enforce the restricted Pod Security Standard and a token-hardened ServiceAccount, deploy a workload hardened enough to be admitted under it, then isolate it with a NetworkPolicy and scope its RBAC. Every field is graded.
Your mission
A drill, not a tutorial: paced and scored like the exam, each task fuses several
CKS techniques, the specs are exact, and hints cost real points. Work in the secure
namespace (already created). The bar is to finish without opening a hint.
You're hardening api end to end — the namespace policy, the workload's identity and
security context, its network exposure, and its RBAC. A single missed field
(readOnlyRootFilesystem, an auto-mounted token, the wrong policy peer) is a missed
mark, exactly as on exam day.
Save typing
kubectl config set-context --current --namespace=secure